New Ransomware Scheme Targets Corporate Printers and BitLocker

New Ransomware Scheme Targets Corporate Printers and BitLocker

First seen 21 Jul 2026, 16:27 UTC CyberintSecurelistKaspersky 75% similarity 51.9

Article Content

Browse articles
ThreatCluster

In June 2026, a series of ransomware attacks were reported in Colombia and Mexico, where attackers exploited misconfigured corporate printers and remote desktop services to encrypt data using BitLocker. The attackers demanded ransoms as low as $3,000, with victims receiving printed ransom notes. The Colombian incident involved an 8 TB storage device containing critical financial data, which was encrypted after the attackers gained control via an exposed RDP service. The affected organizations faced challenges in forensic analysis due to their quick restoration of systems, leading to a loss of evidence. This incident highlights the vulnerabilities associated with open RDP ports and disabled endpoint protection. Similar tactics were observed in the Mexican incident, indicating a growing trend in ransomware targeting corporate infrastructure through unconventional methods.

Key Points: • Ransomware attacks in Colombia and Mexico exploited corporate printers and BitLocker. • Attackers demanded ransoms as low as $3,000, using printed notes to communicate. • Misconfigured RDP services and disabled endpoint protection facilitated the breaches.

ThreatCluster AI

Timeline

2026-05-01
Ransomware attack in Mexico
A similar ransomware incident occurred, targeting corporate infrastructure and utilizing printed ransom notes.
Securelist
2026-06-01
Ransomware attack in Colombia
Attackers exploited an exposed RDP service to encrypt critical financial data using BitLocker, demanding a $3,000 ransom.
Securelist
Recent
Forensic evidence lost
Victims rushed to restore systems, resulting in the loss of critical forensic evidence needed for analysis.
Securelist

Community

Browse all →